Yocto Project Documentation
 help / color / mirror / Atom feed
From: Paul Barker <paul@pbarker.dev>
To: docs@lists.yoctoproject.org
Cc: Paul Barker <paul@pbarker.dev>
Subject: [PATCH v2 2/3] security-team: Tidy and update section on security team operations
Date: Wed, 03 Jun 2026 20:45:18 +0100	[thread overview]
Message-ID: <20260603-sec-team-v2-2-ee7d2016fbf4@pbarker.dev> (raw)
In-Reply-To: <20260603-sec-team-v2-0-ee7d2016fbf4@pbarker.dev>

The section "What Yocto Security Team does when it receives a security
vulnerability" duplicated information already found in the previous
section "Security Team Operations", so merge the sections and tidy up
the flow of the text.

While we're editing this, Mitre is now just one of the places you can go
to get a CVE assigned, many other CVE Numbering Authorities (CNAs) are
available. They also now have a web form for contact and requesting CVE
assignment so let's link directly to that.

Also drop "If an upstream project does not respond quickly" down a
heading level.

Signed-off-by: Paul Barker <paul@pbarker.dev>
---
 documentation/security-reference/security-team.rst | 26 +++++++---------------
 1 file changed, 8 insertions(+), 18 deletions(-)

diff --git a/documentation/security-reference/security-team.rst b/documentation/security-reference/security-team.rst
index 7ec1dda02e0c..c83ada17eb56 100644
--- a/documentation/security-reference/security-team.rst
+++ b/documentation/security-reference/security-team.rst
@@ -56,31 +56,21 @@ original reporter in the loop. There is also sometimes some coordination for
 handling patches, backporting patches etc, or just understanding the problem
 or what caused it.
 
-When the fix is publicly available, the YP security team member or the
-package maintainer sends patches against the YP code base, following usual
-procedures, including public code review.
-
-What Yocto Security Team does when it receives a security vulnerability
-=======================================================================
-
-The YP Security Team team performs a quick analysis and would usually report
-the flaw to the upstream project. Normally the upstream project analyzes the
-problem. If they deem it a real security problem in their software, they
-develop and release a fix following their own security policy. They may want
-to include the original reporter in the loop. There is also sometimes some
-coordination for handling patches, backporting patches etc, or just
-understanding the problem or what caused it.
-
 The security policy of the upstream project might include a notification to
 Linux distributions or other important downstream projects in advance to
 discuss coordinated disclosure. These mailing lists are normally non-public.
 
 When the upstream project releases a version with the fix, they are responsible
-for contacting `Mitre <https://www.cve.org/>`__ to get a CVE number assigned and
-the CVE record published.
+for contacting an appropriate CVE Numbering Authority (CNA), such as `Mitre
+<https://cveform.mitre.org/>`__, to get a CVE number assigned and the CVE
+record published.
+
+When the fix is publicly available, the YP security team member or the
+package maintainer sends patches against the YP code base, following usual
+procedures, including public code review.
 
 If an upstream project does not respond quickly
-===============================================
+-----------------------------------------------
 
 If an upstream project does not fix the problem in a reasonable time,
 the Yocto's Security Team will contact other interested parties (usually

-- 
2.43.0



  parent reply	other threads:[~2026-06-03 19:45 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-03 19:45 [PATCH v2 0/3] Security team documentation updates Paul Barker
2026-06-03 19:45 ` [PATCH v2 1/3] security-team: Update membership list Paul Barker
2026-06-03 19:45 ` Paul Barker [this message]
2026-06-04  5:33   ` [docs] [PATCH v2 2/3] security-team: Tidy and update section on security team operations Marta Rybczynska
2026-06-04  8:22     ` Paul Barker
2026-06-03 19:45 ` [PATCH v2 3/3] security-team: Add section on multi-project embargoes Paul Barker
2026-06-09  7:27 ` [PATCH v2 0/3] Security team documentation updates Antonin Godard

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260603-sec-team-v2-2-ee7d2016fbf4@pbarker.dev \
    --to=paul@pbarker.dev \
    --cc=docs@lists.yoctoproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox